Tag: microsoft
-
Angriff gegen 120 Unternehmen Kampagne nutzt echte Microsoft-Anmeldung
First seen on security-insider.de Jump to article: www.security-insider.de/phishing-microsoft-teams-echte-login-seite-boesartige-app-berechtigungen-a-2fa1636d91b31c8388f4555881a3fc9f/
-
Microsoft Paid Record $20 Million in Bug Bounties to 562 Security Researchers Worldwide
Microsoft’s Bug Bounty Program awarded over $20 million to 562 security researchers this year, marking the highest total payout and the largest number of recognized researchers in the program’s history. Contributors hailed from 64 countries, highlighting the global nature of coordinated vulnerability disclosure efforts that help protect Microsoft customers worldwide. This represents significant growth over…
-
Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk
Kali365 is turning a legitimate Microsoft login into a gateway to corporate data.The phishing kit targets US organizations with attacker-controlled device codes that victims approve on Microsoft’s real authentication page. Once access and refresh tokens are issued, attackers may retain access to email, documents, and cloud resources, creating a direct path to data exposure, financial…
-
Kali365 Exploits Microsoft Device Login to Access US Corporate Data
Learn how Kali365 has been abusing Microsoft device login to gain OAuth tokens, targeting US firms, and how SOC teams can detect, hunt, and stop these phishing attacks. First seen on hackread.com Jump to article: hackread.com/kali365-exploit-microsoft-device-login-access-us-data/
-
Microsoft Warns Russian Hackers Use Hotel Wi-Fi to Steal Credentials
Microsoft warns Russian hackers are exploiting hotel Wi-Fi to deliver malware, steal credentials, and compromise corporate travelers’ cloud accounts worldwide. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-microsoft-russian-hackers-hotel-wifi/
-
Phishing service spoofs RingCentral to steal Microsoft 365 accounts
The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/phishing-service-spoofs-ringcentral-to-steal-microsoft-365-accounts/
-
Microsoft Project Perception Enters Public Preview: What Security Teams Should Know
Microsoft’s Project Perception brings coordinated AI agents into security operations, raising new questions about permissions, oversight, accuracy, and deployment risk. The post Microsoft Project Perception Enters Public Preview: What Security Teams Should Know appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-microsoft-project-perception-preview/
-
KnowBe4 erweitert Agentensicherheit mit AgentManager auf Claude von Anthropic
KnowBe4 baut die Sicherheit für KI-Agenten auf Claude von Anthropic durch den Agent-Risk-Manager aus. Die neue Integration bietet Echtzeit-Transparenz und automatisierte Bedrohungserkennung zur Steuerung autonomer KI-Agenten. KnowBe4 erweitert dadurch seine Governance-Ebene und baut dabei auf der bestehenden nativen Unterstützung für Microsoft-Copilot auf. Eine knappe Mehrheit von 58 Prozent an befragten Führungskräften im Bereich Cybersicherheit geben laut dem…
-
Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected
The Federal Office for Information Technology and Communications (BIT) said specialists detected anomalies in on-premises Microsoft servers. The Swiss agency could not confirm exactly how the hackers got in. First seen on therecord.media Jump to article: therecord.media/swiss-bit-foitt-hacked-possibly-sharepoint-vulnerabilities
-
Bug-Bounty-Rekord: Microsoft verteilt 20 Millionen US-Dollar an IT-Forscher
Microsoft hat einen neuen Rekord bei der Ausschüttung seiner Bug-Bounty-Prämien aufgestellt. Für die Forscher war das aber nicht unbedingt von Vorteil. First seen on golem.de Jump to article: www.golem.de/news/bug-bounty-rekord-microsoft-verteilt-20-millionen-us-dollar-an-it-forscher-2608-211580.html
-
Barracuda Networks Shows How AI Agents Can Compromise Business Email
Barracuda Networks shows how attackers could hijack Microsoft Copilot to access sensitive emails, impersonate executives and execute convincing business email compromise attacks. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/barracuda-networks-shows-how-ai-agents-can-compromise-business-email/
-
Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malware
Midnight Blizzard, the Russian threat actor tied to the country’s foreign intelligence service, has spent months targeting users of public Wi-Fi networks at places like … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/04/midnight-blizzard-hotel-wi-fi-networks-hacking/
-
Microsoft shortens NuGet API key lifetime to improve supply chain security
Microsoft is reducing the lifetime of new NuGet.org API keys from 365 days to 30 days starting August 17, 2026, to improve the security of NuGet, its package repository for … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/04/microsoft-reducing-nuget-api-keys-lifetime/
-
ChocoShell Steals Microsoft 365 Tokens and Browser Sessions From Travelers
ChocoShell is a PowerShell-based infostealer used in Microsoft’s newly disclosed “CaptiveCrunch” campaign to steal Microsoft 365 tokens, browser sessions, and Wi”‘Fi credentials from travelers connecting to compromised hospitality networks worldwide. The operation, dubbed “CaptiveCrunch,” poisons DNS and HTTP flows on guest networks so that travelers attempting to reach legitimate Microsoft 365 or update endpoints are…
-
Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hotel-wi-fi-attacks-use-custom-malware-to-breach-microsoft-365-accounts/
-
Travelers Beware: Russian Intel Hacking Hotel Wi-Fi
Russian Intelligence Hackers Capture Captive Portals. Hackers are using hotel Wi-Fi networks across the United States, India and Saudi Arabia to steal credentials, exfiltrate data and spread malware onto personal devices, according to Microsoft and ReliaQuest. Microsoft’s threat intelligence arm began tracking the threat in early May. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/travelers-beware-russian-intel-hacking-hotel-wi-fi-a-32405
-
The Best Agentic SOC for Microsoft Sentinel in 2026 (and Where Security Copilot Fits)
The 8 best agentic SOC platforms for Microsoft Sentinel in 2026, compared. What Security Copilot’s agents do today, GA versus preview, and where the gap is. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/the-best-agentic-soc-for-microsoft-sentinel-in-2026-and-where-security-copilot-fits/
-
Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says
Russian state-sponsored hackers have been compromising hotel Wi-Fi networks around the world to steal travelers’ login credentials and infect devices with espionage malware, Microsoft said. First seen on therecord.media Jump to article: therecord.media/russian-wifi-hackers-hotels
-
Microsoft warnt: Russische Hacker verbreiten Malware über öffentliche WLANs
Die Angreifer haben wohl WLAN-Netze von Hotels, Flughäfen und anderen Einrichtungen infiltriert, um Daten abzugreifen und Malware zu verbreiten. First seen on golem.de Jump to article: www.golem.de/news/microsoft-warnt-russische-hacker-verbreiten-malware-ueber-oeffentliche-wlans-2608-211540.html
-
Russian Hackers Exploit Hotel Wi-Fi in New CaptiveCrunch Espionage Campaign
Microsoft Threat Intelligence has uncovered CaptiveCrunch, a cyber espionage campaign linked to Storm-2945, a subgroup of Midnight Blizzard, the Russian state-linked threat actor associated with Russia’s Foreign Intelligence Service (SVR). First seen on thecyberexpress.com Jump to article: thecyberexpress.com/captivecrunch-midnight-blizzard/
-
Elastic Defend now covers 800+ vulnerable drivers, with automated troubleshooting and ARM support
Attackers reaching for kernel access on a Windows machine bring a driver Microsoft already trusts. It is signed, it loads, and it carries a known flaw. That flaw gives them … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/03/elastic-defend-vulnerable-driver-detection/
-
Security Affairs newsletter Round 588 by Pierluigi Paganini INTERNATIONAL EDITION
Tags: adobe, email, flaw, hacker, international, microsoft, russia, vulnerability, WeeklyReview, wifiA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens Adobe fixed a maximum-severity vulnerability flaw in…
-
Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens
Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS…
-
To Ban or Not Ban Chinese Open-Weight AI Models
Tags: ai, backdoor, china, control, cybersecurity, data, defense, finance, government, infrastructure, international, malicious, microsoft, military, network, nvidia, open-source, openai, regulation, risk, software, supply-chain, technology, usaShould the US ban American companies from using Chinese open-weight AI models? That is the ugly question. US officials have openly expressed concerns and a desire to implement regulations. The technology community has aggressively responded, with over 20 leading AI companies, including Microsoft, Nvidia, Meta, and Dell, urging legislators not to rush imposing restrictions on…
-
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report.Researchers track the operation as CaptiveCrunch and attribute it to Storm-2945. It assesses Storm-2945 to be an operational sub-cluster of Midnight…
-
ShinyHunters Claims Brinks Home Salesforce Data Theft
ShinyHunters claims it breached Brinks Home through a Microsoft Entra vishing attack. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/shinyhunters-claims-brinks-home-salesforce-data-theft/
-
The Security Interviews: Nicole Darden Ford, Microsoft
As a black woman in the white, male-dominated world of cyber security, Microsoft’s Nicole Darden Ford has worked hard to carve out her space in the room. She talks about developing confidence and self-belief, building community, and leading with humility First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366646265/The-Security-Interviews-Nicole-Darden-Ford-Microsoft
-
Vishing-Kampagne über Microsoft Teams mündet in Chaos-Ransomware
Angreifer geben sich über Microsoft Teams als IT-Support aus, um sich Fernzugriff auf Firmengeräte zu verschaffen. Darauf folgte der Einsatz der Ransomware Chaos. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/microsoft-teams-chaos
-
Forscher finden Masterkey für Vollzugriff auf Azure-Datenbanken
Tags: microsoftMit dem Key hätten Angreifer alle Datenbanken bei Microsofts Datenbankdienst Azure Cosmos DB auslesen und manipulieren können – auch die von Microsoft. First seen on golem.de Jump to article: www.golem.de/news/microsoft-forscher-finden-masterkey-fuer-vollzugriff-auf-azure-datenbanken-2607-211473.html
-
Top 10 Companies to Hire Power BI Developers in 2026
Compare 10 Power BI development companies for 2026, covering DAX, Microsoft Fabric, data engineering, security, compliance, AI, and enterprise BI project needs. First seen on hackread.com Jump to article: hackread.com/top-companies-hire-power-bi-developers-in-2026/

